Soru

Zorluk: ZorNetwork Security Monitoring and Alerting

During a routine traffic audit of an enterprise perimeter router, a security team examines the following network telemetry log generated by a passive Network Security Monitoring (NSM) sensor inspecting outbound UDP traffic:

Timestamp: 2026-07-27T14:22:01Z
Sensor_ID: NSM-PERIMETER-02
Src_IP: 10.4.18.99 (Internal Workstation)
Dst_IP: 198.51.100.45 (External Name Server)
Proto/Port: UDP/53
Query_Type: TXT
Query_String: a1b2c3d4e5f67890abcdef1234567890.sub.exfil-domain.example
Packet_Count: 14,250 queries/5 min
Avg_Payload_Size: 480 bytes

Which of the following is the most accurate assessment of the threat indicated by this alert and the security operational classification of the sensor mechanism?

  1. The traffic indicates network data exfiltration using DNS covert tunneling, and the monitoring sensor operates as a detective security control.Cevap
  2. B
    The traffic indicates an active SQL injection attack targeting an external database, and the monitoring sensor operates as a detective security control.
  3. C
    The traffic indicates network data exfiltration using DNS covert tunneling, and the monitoring sensor operates as a preventive security control.
  4. D
    The traffic indicates a host memory buffer overflow exploit, and the incident should be remediated by deploying inline host-based application patches.

Cevap

The traffic indicates network data exfiltration using DNS covert tunneling, and the monitoring sensor operates as a detective security control.
The correct option accurately identifies the high-frequency UDP/53 TXT query anomaly as DNS covert tunneling used for exfiltrating data across network boundaries. It also correctly categorizes the passive network telemetry sensor as a detective security control because it gathers log evidence and triggers alerts without intercepting or dropping packets inline.

Adım Adım Çözüm

1
Analyze the protocol, query type, payload length, and traffic volume in the telemetry log.
The log reveals an abnormally high volume (14,250 queries within 5 minutes) of UDP port 53 TXT record requests carrying long encoded subdomains to an external destination.
Legitimate DNS resolution consists of low-volume, short lookup requests. Large payloads sent rapidly via TXT queries strongly indicate DNS tunneling used for covert data exfiltration.
2
Differentiate between database/web application exploit traffic and network-level covert tunneling.
The payload is encoded data embedded inside domain subdomains for DNS routing, not relational database manipulation queries (SQL injection).
DNS tunneling encapsulates data within protocol packets to bypass perimeter firewalls, distinct from web application injection vulnerabilities.
3
Classify the operational role of the passive Network Security Monitoring (NSM) sensor.
The passive NSM sensor observes network traffic and records telemetry/alerts, serving a detective control function.
Preventive controls block traffic inline (like firewalls or NIPS), whereas passive network monitoring mechanisms detect and report events.

Anahtar Kavram

DNS Covert Tunneling Detection and Detective Security Controls
Bu soruyu puanla